Your comprehensive guide to data protection rights under the General Data Protection Regulation.
Effective Date: September 5, 2025
The General Data Protection Regulation (GDPR) provides comprehensive data protection rights for individuals in the European Economic Area (EEA), United Kingdom, and Switzerland. RadPro AI is committed to protecting your privacy and ensuring full compliance with GDPR requirements, regardless of where you are located.
Important: This page outlines your rights under GDPR. For complete information about how we collect, use, and protect your data, please also review our Privacy Policy and Terms of Service. If you are a covered entity under HIPAA, additional protections apply as outlined in our Business Associate Agreement.
RadPro AI, a trade name of Radiology Pro AI Corp., an Ontario corporation, is the data controller responsible for processing your personal data under the General Data Protection Regulation (GDPR). We are located in Canada, and process data of users in the European Economic Area (EEA), United Kingdom, and Switzerland in accordance with GDPR requirements.
Our commitment to data protection extends across all jurisdictions where we operate. We maintain comprehensive data processing records, implement appropriate technical and organizational measures, and ensure transparency in all our data processing activities.
Contact Information: Company: Radiology Pro AI Corp. (RadPro AI) Location: Canada Email: admin@radpro.ai Website: https://radpro.ai
We process your personal data only when we have a valid legal basis under GDPR Article 6. Our primary legal bases include:
Consent (Article 6(1)(a)): We process your data based on your explicit consent when you create an account, use our services, or opt in to marketing communications. You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Contract Performance (Article 6(1)(b)): Processing is necessary to perform our contract with you, including providing our radiology reporting assistant services, managing your account, and delivering the features you have subscribed to.
Legitimate Interests (Article 6(1)(f)): We process data based on our legitimate interests in improving our services, ensuring security, preventing fraud, and conducting business analytics, provided these interests do not override your fundamental rights and freedoms.
Legal Obligation (Article 6(1)(c)): We process data when necessary to comply with legal obligations, including healthcare regulations, tax laws, and data protection requirements.
For special categories of personal data (including health data), we rely on additional legal bases under GDPR Article 9, including explicit consent and processing necessary for healthcare purposes.
Under the GDPR, you have comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights:
RIGHT TO ACCESS (Article 15) You have the right to obtain confirmation as to whether we process your personal data and, where that is the case, access to your personal data and information about the processing. This includes the right to receive a copy of your personal data undergoing processing. We will provide the first copy free of charge, though we may charge a reasonable fee for additional copies.
RIGHT TO RECTIFICATION (Article 16) You have the right to obtain the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of processing, you also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
RIGHT TO ERASURE / "RIGHT TO BE FORGOTTEN" (Article 17) You have the right to obtain the erasure of your personal data without undue delay where one of the following grounds applies: - The personal data are no longer necessary for the purposes for which they were collected - You withdraw consent and there is no other legal ground for processing - You object to processing and there are no overriding legitimate grounds - The personal data have been unlawfully processed - Erasure is required for compliance with a legal obligation
Note: This right is subject to certain limitations, including where we must retain data for compliance with legal obligations (such as HIPAA's 6-year retention requirement for audit logs), for the establishment, exercise, or defense of legal claims, or for archiving purposes in the public interest.
RIGHT TO RESTRICT PROCESSING (Article 18) You have the right to obtain restriction of processing where one of the following applies: - You contest the accuracy of the personal data (restriction for a period enabling verification) - Processing is unlawful and you oppose erasure, requesting restriction instead - We no longer need the data but you require it for legal claims - You have objected to processing pending verification of whether legitimate grounds override yours
RIGHT TO DATA PORTABILITY (Article 20) You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON, CSV) and have the right to transmit that data to another controller without hindrance from us, where: - Processing is based on consent or contract, and - Processing is carried out by automated means
We provide easy export functionality within your account settings to facilitate this right.
RIGHT TO OBJECT (Article 21) You have the right to object, on grounds relating to your particular situation, to processing of your personal data based on legitimate interests or performance of a task in the public interest. We will no longer process your data unless we demonstrate compelling legitimate grounds which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
You have the absolute right to object to processing for direct marketing purposes at any time.
RIGHTS RELATED TO AUTOMATED DECISION-MAKING AND PROFILING (Article 22) You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. While RadPro AI uses artificial intelligence to assist with radiology reports, all AI-generated content must be reviewed and approved by a qualified healthcare professional before use in patient care. We do not make automated decisions that have legal or similarly significant effects without human intervention.
To exercise any of these rights, please contact us at admin@radpro.ai. We will respond to your request within one month, though this may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay.
As RadPro AI operates globally and uses third-party services, your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including Canada and the United States. These countries may not provide the same level of data protection as your home country.
To ensure your data receives adequate protection when transferred internationally, we implement the following safeguards:
STANDARD CONTRACTUAL CLAUSES (SCCs) We use the European Commission's Standard Contractual Clauses (SCCs) for transfers of personal data to third countries. These are contractual commitments between companies transferring personal data, binding them to protect the privacy and security of your data. We use the SCCs adopted by the European Commission on June 4, 2021.
ADEQUACY DECISIONS Where possible, we transfer data to countries that have been deemed by the European Commission to provide an adequate level of data protection. We monitor adequacy decisions and adapt our transfer mechanisms accordingly.
SUPPLEMENTARY MEASURES In addition to SCCs, we implement supplementary technical, organizational, and contractual measures to ensure that data transferred outside the EEA receives a level of protection essentially equivalent to that guaranteed within the EEA. These measures include: - End-to-end encryption for data in transit (TLS 1.3) - Strong encryption at rest (AES-256) - Strict access controls and authentication mechanisms - Regular security assessments and audits - Data minimization and pseudonymization where appropriate - Contractual obligations on third-party processors
CANADIAN DATA PROTECTION As a Canadian company, we comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), which is recognized as providing substantial similarity to EU data protection requirements. Canada benefits from transitional adequacy decisions for commercial transfers.
THIRD-PARTY SERVICES Our primary third-party services that may involve international transfers include: - AI Model Hosting: OpenRouter (with SCCs and encryption) - Payment Processing: Stripe (Privacy Shield certified and SCC-compliant) - Cloud Infrastructure: AWS and Fly.io (GDPR-compliant with SCCs)
You have the right to obtain information about the safeguards we have implemented for international transfers by contacting admin@radpro.ai. We can provide copies of relevant adequacy decisions, SCCs, or information about other transfer mechanisms upon request.
We have appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with GDPR requirements. Our DPO is responsible for:
- Monitoring compliance with GDPR and other data protection laws - Advising on data protection impact assessments - Cooperating with supervisory authorities - Acting as a contact point for supervisory authorities and data subjects - Providing guidance on data protection obligations - Managing data breach notifications and responses
You have the right to contact our Data Protection Officer directly regarding: - Questions about how we process your personal data - Concerns about your data protection rights - Complaints about our data processing activities - Requests to exercise your GDPR rights - Data protection impact assessments - Data breach notifications
Contact Our DPO: Email: admin@radpro.ai Subject Line: "ATTN: Data Protection Officer" Mail: Data Protection Officer RadPro AI Canada
When contacting our DPO, please include: - Your full name and contact information - Description of your inquiry or concern - Any relevant account information (if applicable) - Preferred method and language for response
Our DPO will respond to your inquiry within one month. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension and the reasons for delay.
The DPO operates independently and reports directly to the highest management level. Our DPO is not dismissed or penalized for performing their tasks and has the necessary resources and access to personal data and processing operations to fulfill their duties effectively.
You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data infringes GDPR.
While we encourage you to contact us first at admin@radpro.ai to resolve any concerns, you have the right to lodge a complaint directly with a supervisory authority at any time.
EU/EEA SUPERVISORY AUTHORITIES Each EU Member State has its own supervisory authority. You can find the appropriate authority for your country at: https://edpb.europa.eu/about-edpb/board/members_en
Some prominent supervisory authorities include:
Ireland (for many tech companies): Data Protection Commission 21 Fitzwilliam Square South Dublin 2, D02 RD28 Ireland Phone: +353 57 868 4800 Email: info@dataprotection.ie Website: www.dataprotection.ie
Germany: The Federal Commissioner for Data Protection and Freedom of Information (BfDI) Graurheindorfer Str. 153 53117 Bonn Germany Phone: +49 228 997799-0 Email: poststelle@bfdi.bund.de Website: www.bfdi.bund.de
France: Commission Nationale de l'Informatique et des Libertés (CNIL) 3 Place de Fontenoy TSA 80715 75334 Paris Cedex 07 France Phone: +33 1 53 73 22 22 Website: www.cnil.fr
United Kingdom: Information Commissioner's Office (ICO) Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF United Kingdom Phone: +44 303 123 1113 Website: www.ico.org.uk
COMPLAINT PROCESS When lodging a complaint with a supervisory authority, you should provide: - Your contact information - Description of the alleged infringement - Details about the data controller - Any evidence supporting your complaint - Any correspondence with us regarding the issue
The supervisory authority will investigate your complaint and may: - Request information from us - Conduct audits or inspections - Issue warnings or reprimands - Impose administrative fines - Order us to comply with your data subject rights - Impose temporary or permanent processing bans
CANADIAN PRIVACY COMMISSIONER As a Canadian company, you may also lodge a complaint with: Office of the Privacy Commissioner of Canada 30 Victoria Street Gatineau, Quebec K1A 1H3 Canada Phone: 1-800-282-1376 Email: info@priv.gc.ca Website: www.priv.gc.ca
Please note that lodging a complaint with a supervisory authority does not affect your ability to seek judicial remedy or other forms of redress.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
ACCOUNT DATA Active Accounts: Your account information and preferences are retained for the duration of your active account. Inactive Accounts: If you do not log in for 24 months, we may contact you to confirm whether you wish to maintain your account. Deletion Requests: Upon request, we will delete your account and associated personal data within 30 days, subject to legal retention requirements outlined below.
RADIOLOGY REPORT DATA Processed Reports: Radiology reports you choose to save are retained in your account until you delete them or close your account. Temporary Processing Data: Reports processed through our AI but not saved are automatically deleted within 24 hours of processing. PHI-Scrubbed Data: Anonymized report data (with all PHI removed) may be retained for service improvement purposes.
HIPAA COMPLIANCE - 6-YEAR RETENTION To comply with HIPAA requirements, certain records are retained for a minimum of 6 years from the date of creation or last effective date: - Audit logs of PHI access and processing - Security incident records - Compliance documentation - Business Associate Agreement records - Access control records - System activity logs involving PHI
These records are maintained in secure, access-controlled systems and are automatically deleted after the required retention period unless legal proceedings or investigations require extended retention.
PAYMENT AND BILLING DATA Transaction Records: Payment transactions are retained for 7 years to comply with tax laws and accounting requirements. Credit Card Information: We do not store complete credit card numbers. Payment processing is handled by Stripe, which maintains PCI DSS compliance. Invoices: Billing records and invoices are retained for 7 years for accounting and tax purposes.
COMMUNICATIONS Email Correspondence: Support emails and communications are retained for 3 years to maintain service quality and resolve disputes. Marketing Communications: Records of consent and unsubscribe requests are retained indefinitely to ensure compliance with your preferences.
LEGAL AND COMPLIANCE Legal Holds: Data subject to legal proceedings, investigations, or regulatory requests is retained until the matter is resolved. Backup Systems: Data in backup systems may persist for up to 90 days after deletion from production systems but is not accessible for normal operations.
ANALYTICS AND AGGREGATED DATA Anonymized Usage Analytics: Aggregated, anonymized data with no personal identifiers may be retained indefinitely for statistical analysis and service improvement. Performance Metrics: De-identified performance data is retained to improve AI models and service quality.
YOUR RIGHTS REGARDING RETENTION Despite the retention periods outlined above, you have the right to: - Request deletion of your data at any time (subject to legal retention requirements) - Object to processing for legitimate interests - Request restriction of processing during disputes about accuracy or legitimate grounds - Obtain information about specific retention periods for your data
To exercise these rights or request information about retention of your specific data, contact admin@radpro.ai.
AUTOMATED DELETION We implement automated deletion processes to ensure data is not retained longer than necessary: - Daily cleanup of temporary processing files - Monthly review of inactive sessions - Annual audit of retention compliance - Automated deletion of data past retention periods
Our retention policies are regularly reviewed and updated to ensure compliance with evolving legal requirements and best practices in data protection.
Simple steps to exercise your GDPR rights
Request a complete copy of your personal data within 30 days.
Email: admin@radpro.ai with subject "Data Access Request"
Update inaccurate information in your account or records.
Use account settings or email admin@radpro.ai
Request deletion of your account and personal data.
Account settings or email with subject "Deletion Request"
Download your data in standard formats (JSON, CSV).
Use account export feature or request via email
For any questions about your GDPR rights or our data processing activities:
Data Protection Officer
Email: admin@radpro.ai
Subject Line: "ATTN: Data Protection Officer"
Mail:
Data Protection Officer
RadPro AI
Canada
While we strive to address all concerns directly, you have the right to lodge a complaint with a supervisory authority in your jurisdiction. You can find your local authority at:
European Data Protection Board - Supervisory Authorities
Canadian users may also contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca
This GDPR Rights page is part of our commitment to transparency and data protection. For complete information about our data practices, please review our Privacy Policy and Terms of Service. We regularly update our policies to reflect changes in law and best practices.
Last updated: September 25, 2026